Modifying Cisco AnyConnect Split Tunnel via Group Policy

Configure site-to-site and remote access VPN using Cisco Secure Firewall (FTD) and Cisco Secure Client
Answer Correct answer: D — Modify the group policy to configure split tunneling exclusions for the remote access VPN.

An engineer must modify an existing remote access VPN using a Cisco AnyConnect Secure Mobility client solution and a Cisco Secure Firewall. Currently, all the traffic generated by the user is sent to the VPN tunnel and the engineer must now exclude some servers and access them directly instead. Which element must be modified to achieve this goal?

  1. NAT exemption
  2. encryption domain
  3. routing table
  4. group policy Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of where split-tunneling exclusions are defined in Cisco ASA/FTD configurations, specifically distinguishing between NAT rules and group policies.

This page explains how to configure split tunneling for a remote access VPN on Cisco Secure Firewall (FTD) and Cisco AnyConnect clients by modifying the group policy.

Engineers often mistakenly look for 'NAT exemption' or 'routing table' modifications to exclude traffic, but these do not control which traffic enters the tunnel versus the local network.

Community Discussion (3 comments)

luismg 👍 1 Selected: D
The group policy contents the split tunnel so D is the answer.
Premium_Pils 👍 1 Selected: D
ASA -> Configuration > Remote Access VPN > Group Policies -> Advanced > Split Tunneling
klu16 👍 1 Selected: D
Split-tunneling is indeed located under group policy settings.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To exclude specific servers from a remote access VPN tunnel so they are accessed directly via the internet, you must enable and configure split tunneling. On Cisco ASA and FTD devices running AnyConnect, split tunneling settings—including the list of excluded networks—are contained within the Group Policy object. Modifying this policy allows the engineer to define the exclusion list effectively.

Why the Other Options Are Wrong

NAT exemption prevents translation but does not control routing decisions regarding the tunnel interface; it simply ensures traffic isn't translated when it matches a rule. The encryption domain defines what traffic initiates the IPsec phase 1 negotiation (usually site-to-site), not client traffic flows. The routing table determines path selection but cannot be easily modified dynamically per-client without complex static routes; Group Policy is the intended mechanism for client-side routing instructions.

Community Comment Notes

Community consensus strongly supports Group Policy as the correct answer. Users noted that "split tunneling is indeed located under group policy settings" and referenced the configuration path: Configuration > Remote Access VPN > Group Policies. This aligns with standard Cisco AnyConnect deployment practices.

Exam Strategy

When configuring remote access VPNs, always check the Group Policy for client-specific behaviors like split tunneling and DNS settings before looking at global firewall rules or NAT configurations.

Frequently Asked Questions

Where is split tunneling configured in FTD?

Split tunneling and exclusion lists are configured within the Group Policy object under the Advanced settings for Remote Access VPN.

Does NAT exemption stop traffic from going through the tunnel?

No, NAT exemption only prevents address translation. It does not determine whether traffic enters the VPN tunnel or exits locally; Group Policy controls that.

Related Analysis

← Back to 350-701 Study Guide